Go Smart Online Card Checker - Privacy Notice
Reference Point Ltd is committed to protecting and respecting your privacy. This policy, sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
We keep certain basic information when you use the online card checking service and recognise the importance of keeping that information secure and letting you know what we will do with it.
Background
We are an IT provider for organisations in the construction industry who issue CSCS cards or CSCS approved cards. The services include this online checking service located on the website www.gosmart.co.uk (“our website”) which allows the data of cardholders in participating card schemes to be checked online upon the input of certain identifying cardholder information. The services also include an App for which there is a separate privacy notice.
For the purposes of the Retained Regulation (GDPR (EU) 2016/679) (UK GDPR) and the Data Protection Act 2018 (“data protection legislation”):
We are the data controller data we collect about your use of the online checking service.
Contact Details
Our Contact Details: Reference Point Limited, Shire House, Gerrards Cross, SL9 7QN +44 (0) 1753 279 927.
Questions, comments and requests regarding this privacy policy are welcomed and should be addressed for the attention of our Data Protection Officer at dpo@referencepoint.co.uk
Information we may collect from you and purpose for processing
Where you contact us for support, we will use your email address and any other contact details you provide for communicating with you. The details of support requested and provided will be logged for our internal records.
We may also ask you for information when you report a problem with the online card checking service.
We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
If you perform a search using the online check service we will collect and store your IP address and the search criteria you have input into the online check service.
Lawful basis for processing:
We will only use your personal data when the law allows us to.
- We may use your personal data to perform the contract we have entered into with you or in order to take steps at your request to enter into a contract with you (Basis: Art 6(b) UK GDPR).
- We and any third parties with whom we share your personal data may also find it necessary to process your data for legitimate interests we pursue (Basis: Art 6(f) UK GDPR), for example, to improve our services.
- We may also process your personal data based on compliance with a mandatory legal obligation (Basis: Art 6 (c) UK GDPR) including, for example, accounting and tax requirements which are subject to strict internal policies (such as retention periods).
- Where we do not rely on another legal basis, we may process your personal data based on consent you provide (Basis: Art 6(a) UK GDPR).
The recipients or categories of recipients of personal data:
We will share your personal data with third parties where required by law or where we have another legitimate interest in doing so.
We may disclose your personal information to third parties:
- In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets
- If we are under a duty to disclose or share your personal data in order to comply with any legal obligation. This includes exchanging information with other companies and organisations for the purposes of fraud protection.
Where we store your personal data and transfers out of the UK:
The data that we collect from you will be stored within the UK and may be processed by staff operating within the UK who work for us and any relevant sub-processors.
We will not transfer any data that we collect or receive from you that constitutes personal data outside of the UK unless there are appropriate safeguards, the transfer is based on adequacy (decision or regulations) as set out in the data protection legislation or the transfer otherwise complies with the data protection legislation. Such transfers may involve, for example, our use of third party services allowing us to send e-mails or automated SMS messages which make use of facilities in third countries to process and store data.
Security:
We will take all steps reasonably necessary to ensure that your data provided to us is treated securely and in accordance with this privacy notice.
All information you provide to us is stored on our or our sub-contractors' secure servers. Where we have given you (or where you have chosen) a password or key which enables you to access the online card checking service, you are responsible for keeping this password or key confidential.
We take steps to protect the information that we receive from you from loss, misuse, and unauthorised access or disclosure. These steps take into account the sensitivity of the information we receive, process and store, and the current state of technology.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do what we reasonably can to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use reasonable procedures and security features to try to prevent unauthorised access.
Retention period and criteria used to determine the retention period:
- We will only retain your personal data for as long as necessary to fulfil the purpose for which it was collected, including for the purposes of satisfying any legal, accounting or reporting requirements.
- Encrypted back ups: We will retain encrypted back up tapes for a maximum of 3 years from the termination of our contract with you, if any, or from when you cease to use our services. This time limit is set in line with the limitation period for possible legal claims which may require such data in order to be investigated and/or defended against.
Your rights:
You have the right to:
- Request access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information (commonly known as “the right to be forgotten”). This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing.
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal information to another party.
Where our processing is based on your explicit consent to our processing, you have the right to withdraw such consent (this will not affect the lawfulness of processing prior to the withdrawal of your consent).
If you wish to exercise any of these rights please contact our Data Protection Officer at dpo@referencepoint.co.uk
We will inform you (before collecting your data) if we intend to use your data for marketing purposes or if we intend to disclose your information to any third party for such purposes and you can withhold your consent to and prevent such processing by not checking certain boxes on the forms we use to collect your data. You can also exercise the right to prevent such processing at any time by contacting us at support@gosmart.co.uk
Third Party Links
This notice only applies to the online card checking service. If you leave our site via a link or otherwise, you will be subject to the privacy policy of that website provider. We have no control over such policies or terms of such websites and we do not accept any responsibility or liability for them. You should check the relevant policies and terms before continuing to access such sites.
Complaints to Information Commissioner: You have the right to lodge a complaint about our processing with the Information Commissioner.
Consequences of failure to provide personal data: Your provision of personal data to us may be a requirement necessary for you to enter into a contract with us. If you fail to provide certain information when requested, we may not be able to perform the contract we have entered into with you.
Changes to our privacy notice
Any changes we may make to our privacy notice in the future will be posted on the relevant page on our site and, where appropriate, notified to you by e-mail. However, we advise that you check on our site regularly to keep up to date with any necessary changes.